CAUSE
This vulnerability results from the way in which Internet Explorer handles ActiveX objects, specifically with the
codeBase property. If you set the CODEBASE property of an object or program to the file path of a local program file, that program file can be invoked without prompting the user. This occurs because when the HTML is processed, it tries to bind to the source. This results in the program file being run because the CODEBASE tag and the OBJECT tag run in the same zone (for example, the My Computer zone). In this case, they should be running in the Internet zone, which would prevent local programs from being run on the user's computer.
RESOLUTION
Internet Explorer 6
To resolve this problem, obtain the latest service pack for Internet Explorer 6. For additional information, click the following article number to view the article in the
Microsoft Knowledge Base:
328548 How to Obtain the Latest Internet Explorer 6 Service Pack
The update for this problem is included in the "March 28, 2002, Cumulative Patch for Internet Explorer." For additional information about how to obtain this patch, click the article number below
to view the article in the Microsoft Knowledge Base:
319182 MS02-015: March 28, 2002, Cumulative Patch for Internet Explorer
Internet Explorer 5.5 Service Pack 2
The update for this problem is included in the "March 28, 2002, Cumulative Patch for Internet Explorer." For additional information about how to obtain this patch, click the article number below
to view the article in the Microsoft Knowledge Base:
319182 MS02-015: March 28, 2002, Cumulative Patch for Internet Explorer
Internet Explorer 5.5 Service Pack 1
The update for this problem is included in the "March 28, 2002, Cumulative Patch for Internet Explorer." For additional information about how to obtain this patch, click the article number below
to view the article in the Microsoft Knowledge Base:
319182 MS02-015: March 28, 2002, Cumulative Patch for Internet Explorer
Internet Explorer 5.01 Service Pack 2 (on Windows 2000 and Windows NT 4.0 only)
This update is only for customers running Internet Explorer 5.01
Service Pack 2 on Windows 2000
Service Pack 2 or Windows NT 4.0
Service Pack 6a. If you are running Internet Explorer 5.01 on any other version of Windows, upgrade to Internet Explorer 5.5
Service Pack 2 or
later, and then apply this update.
The update for this problem is included in the "March 28, 2002, Cumulative Patch for Internet Explorer." For additional information about how to obtain this patch, click the article number below
to view the article in the Microsoft Knowledge Base:
319182 MS02-015: March 28, 2002, Cumulative Patch for Internet Explorer